Linux Hardware Monitor development
 help / color / mirror / Atom feed
* [PATCH] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths
@ 2026-08-24  9:05 liupeng
  2026-08-24  9:12 ` sashiko-bot
  2026-09-17 22:10 ` lyude
  0 siblings, 2 replies; 11+ messages in thread
From: liupeng @ 2026-08-24  9:05 UTC (permalink / raw)
  To: Lyude Paul, Danilo Krummrich, Maarten Lankhorst, Maxime Ripard,
	Thomas Zimmermann, David Airlie, Simona Vetter, Guenter Roeck,
	open list:DRM DRIVER FOR NVIDIA GEFORCE/QUADRO GPUS,
	open list:DRM DRIVER FOR NVIDIA GEFORCE/QUADRO GPUS, open list,
	open list:HARDWARE MONITORING:Keyword:(devm_)?hwmon_device_(un)?register(|_with_groups|_with_info)
  Cc: liupeng

In nouveau_debugfs_init(), if nvif_object_ctor() fails, the previously
allocated drm->debugfs is leaked because the function returns the
error code directly.

In nouveau_hwmon_init(), if hwmon_device_register_with_info() fails,
the allocated hwmon structure is leaked because the function returns
the error code directly.

Fix both by freeing the allocated memory and clearing the pointer on
the error paths.

Signed-off-by: liupeng <liupeng01@kylinos.cn>
---
 drivers/gpu/drm/nouveau/nouveau_debugfs.c | 15 ++++++++++++---
 drivers/gpu/drm/nouveau/nouveau_hwmon.c   |  2 ++
 2 files changed, 14 insertions(+), 3 deletions(-)

diff --git a/drivers/gpu/drm/nouveau/nouveau_debugfs.c b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
index 47d5579c568d..88223931f382 100644
--- a/drivers/gpu/drm/nouveau/nouveau_debugfs.c
+++ b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
@@ -295,13 +295,22 @@ nouveau_drm_debugfs_init(struct drm_minor *minor)
 int
 nouveau_debugfs_init(struct nouveau_drm *drm)
 {
+	int ret;
+
 	drm->debugfs = kzalloc_obj(*drm->debugfs);
 	if (!drm->debugfs)
 		return -ENOMEM;
 
-	return nvif_object_ctor(&drm->client.device.object, "debugfsCtrl", 0,
-				NVIF_CLASS_CONTROL, NULL, 0,
-				&drm->debugfs->ctrl);
+	ret = nvif_object_ctor(&drm->client.device.object, "debugfsCtrl", 0,
+			       NVIF_CLASS_CONTROL, NULL, 0,
+			       &drm->debugfs->ctrl);
+	if (ret) {
+		kfree(drm->debugfs);
+		drm->debugfs = NULL;
+		return ret;
+	}
+
+	return 0;
 }
 
 void
diff --git a/drivers/gpu/drm/nouveau/nouveau_hwmon.c b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
index 726397ab035d..ffbe7f542ab0 100644
--- a/drivers/gpu/drm/nouveau/nouveau_hwmon.c
+++ b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
@@ -697,6 +697,8 @@ nouveau_hwmon_init(struct drm_device *dev)
 	if (IS_ERR(hwmon_dev)) {
 		ret = PTR_ERR(hwmon_dev);
 		NV_ERROR(drm, "Unable to register hwmon device: %d\n", ret);
+		drm->hwmon = NULL;
+		kfree(hwmon);
 		return ret;
 	}
 
-- 
2.53.0


^ permalink raw reply related	[flat|nested] 11+ messages in thread

* Re: [PATCH] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths
  2026-08-24  9:05 [PATCH] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths liupeng
@ 2026-08-24  9:12 ` sashiko-bot
  2026-09-17 22:10 ` lyude
  1 sibling, 0 replies; 11+ messages in thread
From: sashiko-bot @ 2026-08-24  9:12 UTC (permalink / raw)
  To: liupeng; +Cc: linux-hwmon, dri-devel

> In nouveau_debugfs_init(), if nvif_object_ctor() fails, the previously
> allocated drm->debugfs is leaked because the function returns the
> error code directly.
> 
> In nouveau_hwmon_init(), if hwmon_device_register_with_info() fails,
> the allocated hwmon structure is leaked because the function returns
> the error code directly.
> 
> Fix both by freeing the allocated memory and clearing the pointer on
> the error paths.
> 
> Signed-off-by: liupeng <liupeng01@kylinos.cn>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260824090505.49913-1-liupeng01@kylinos.cn?part=1


^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: [PATCH] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths
  2026-08-24  9:05 [PATCH] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths liupeng
  2026-08-24  9:12 ` sashiko-bot
@ 2026-09-17 22:10 ` lyude
  2026-09-22  4:40   ` [PATCH v2] " liupeng
  1 sibling, 1 reply; 11+ messages in thread
From: lyude @ 2026-09-17 22:10 UTC (permalink / raw)
  To: liupeng, Danilo Krummrich, Maarten Lankhorst, Maxime Ripard,
	Thomas Zimmermann, David Airlie, Simona Vetter, Guenter Roeck,
	open list:DRM DRIVER FOR NVIDIA GEFORCE/QUADRO GPUS,
	open list:DRM DRIVER FOR NVIDIA GEFORCE/QUADRO GPUS, open list,
	open list:HARDWARE   MONITORING:Keyword:(devm_)?hwmon_device_(un)?register(|_with_groups|_with_info)

Mind adding the proper Fixes: tags and Cc: tags here?

On Mon, 2026-08-24 at 17:05 +0800, liupeng wrote:
> In nouveau_debugfs_init(), if nvif_object_ctor() fails, the
> previously
> allocated drm->debugfs is leaked because the function returns the
> error code directly.
> 
> In nouveau_hwmon_init(), if hwmon_device_register_with_info() fails,
> the allocated hwmon structure is leaked because the function returns
> the error code directly.
> 
> Fix both by freeing the allocated memory and clearing the pointer on
> the error paths.
> 
> Signed-off-by: liupeng <liupeng01@kylinos.cn>
> ---
>  drivers/gpu/drm/nouveau/nouveau_debugfs.c | 15 ++++++++++++---
>  drivers/gpu/drm/nouveau/nouveau_hwmon.c   |  2 ++
>  2 files changed, 14 insertions(+), 3 deletions(-)
> 
> diff --git a/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> index 47d5579c568d..88223931f382 100644
> --- a/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> +++ b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> @@ -295,13 +295,22 @@ nouveau_drm_debugfs_init(struct drm_minor
> *minor)
>  int
>  nouveau_debugfs_init(struct nouveau_drm *drm)
>  {
> +	int ret;
> +
>  	drm->debugfs = kzalloc_obj(*drm->debugfs);
>  	if (!drm->debugfs)
>  		return -ENOMEM;
>  
> -	return nvif_object_ctor(&drm->client.device.object,
> "debugfsCtrl", 0,
> -				NVIF_CLASS_CONTROL, NULL, 0,
> -				&drm->debugfs->ctrl);
> +	ret = nvif_object_ctor(&drm->client.device.object,
> "debugfsCtrl", 0,
> +			       NVIF_CLASS_CONTROL, NULL, 0,
> +			       &drm->debugfs->ctrl);
> +	if (ret) {
> +		kfree(drm->debugfs);
> +		drm->debugfs = NULL;
> +		return ret;
> +	}
> +
> +	return 0;
>  }
>  
>  void
> diff --git a/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> index 726397ab035d..ffbe7f542ab0 100644
> --- a/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> +++ b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> @@ -697,6 +697,8 @@ nouveau_hwmon_init(struct drm_device *dev)
>  	if (IS_ERR(hwmon_dev)) {
>  		ret = PTR_ERR(hwmon_dev);
>  		NV_ERROR(drm, "Unable to register hwmon device:
> %d\n", ret);
> +		drm->hwmon = NULL;
> +		kfree(hwmon);
>  		return ret;
>  	}
>  


^ permalink raw reply	[flat|nested] 11+ messages in thread

* [PATCH v2] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths
  2026-09-17 22:10 ` lyude
@ 2026-09-22  4:40   ` liupeng
  2026-09-22  4:46     ` sashiko-bot
  2026-10-08 21:45     ` lyude
  0 siblings, 2 replies; 11+ messages in thread
From: liupeng @ 2026-09-22  4:40 UTC (permalink / raw)
  To: lyude, dakr
  Cc: maarten.lankhorst, mripard, tzimmermann, airlied, simona, linux,
	nouveau, bskeggs, dri-devel, nouveau, linux-kernel, linux-hwmon,
	stable, liupeng

In nouveau_debugfs_init(), if nvif_object_ctor() fails, the previously
allocated drm->debugfs is leaked because the function returns the
error code directly.

In nouveau_hwmon_init(), if hwmon_device_register_with_info() fails,
the allocated hwmon structure is leaked because the function returns
the error code directly.

Fix both by freeing the allocated memory and clearing the pointer on
the error paths.

Fixes: b126a200e9db ("drm/nouveau/debugfs: we need a ctrl object for debugfs")
Fixes: b9ed919f1c8f ("drm/nouveau/drm/pm: remove everything except the hwmon interfaces to THERM")
Cc: stable@vger.kernel.org
Signed-off-by: liupeng <liupeng01@kylinos.cn>
---
Changes in v2:
- Add Fixes: tags for the commits that introduced the leaks
- Add Cc: stable@vger.kernel.org for stable backporting

 drivers/gpu/drm/nouveau/nouveau_debugfs.c | 15 ++++++++++++---
 drivers/gpu/drm/nouveau/nouveau_hwmon.c   |  2 ++
 2 files changed, 14 insertions(+), 3 deletions(-)

diff --git a/drivers/gpu/drm/nouveau/nouveau_debugfs.c b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
index 47d5579c568d..88223931f382 100644
--- a/drivers/gpu/drm/nouveau/nouveau_debugfs.c
+++ b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
@@ -295,13 +295,22 @@ nouveau_drm_debugfs_init(struct drm_minor *minor)
 int
 nouveau_debugfs_init(struct nouveau_drm *drm)
 {
+	int ret;
+
 	drm->debugfs = kzalloc_obj(*drm->debugfs);
 	if (!drm->debugfs)
 		return -ENOMEM;
 
-	return nvif_object_ctor(&drm->client.device.object, "debugfsCtrl", 0,
-				NVIF_CLASS_CONTROL, NULL, 0,
-				&drm->debugfs->ctrl);
+	ret = nvif_object_ctor(&drm->client.device.object, "debugfsCtrl", 0,
+			       NVIF_CLASS_CONTROL, NULL, 0,
+			       &drm->debugfs->ctrl);
+	if (ret) {
+		kfree(drm->debugfs);
+		drm->debugfs = NULL;
+		return ret;
+	}
+
+	return 0;
 }
 
 void
diff --git a/drivers/gpu/drm/nouveau/nouveau_hwmon.c b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
index 726397ab035d..ffbe7f542ab0 100644
--- a/drivers/gpu/drm/nouveau/nouveau_hwmon.c
+++ b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
@@ -697,6 +697,8 @@ nouveau_hwmon_init(struct drm_device *dev)
 	if (IS_ERR(hwmon_dev)) {
 		ret = PTR_ERR(hwmon_dev);
 		NV_ERROR(drm, "Unable to register hwmon device: %d\n", ret);
+		drm->hwmon = NULL;
+		kfree(hwmon);
 		return ret;
 	}
 
-- 
2.53.0


^ permalink raw reply related	[flat|nested] 11+ messages in thread

* Re: [PATCH v2] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths
  2026-09-22  4:40   ` [PATCH v2] " liupeng
@ 2026-09-22  4:46     ` sashiko-bot
  2026-10-08 21:45     ` lyude
  1 sibling, 0 replies; 11+ messages in thread
From: sashiko-bot @ 2026-09-22  4:46 UTC (permalink / raw)
  To: liupeng; +Cc: linux-hwmon, dri-devel

> In nouveau_debugfs_init(), if nvif_object_ctor() fails, the previously
> allocated drm->debugfs is leaked because the function returns the
> error code directly.
> 
> In nouveau_hwmon_init(), if hwmon_device_register_with_info() fails,
> the allocated hwmon structure is leaked because the function returns
> the error code directly.
> 
> Fix both by freeing the allocated memory and clearing the pointer on
> the error paths.
> 
> Fixes: b126a200e9db ("drm/nouveau/debugfs: we need a ctrl object for debugfs")
> Fixes: b9ed919f1c8f ("drm/nouveau/drm/pm: remove everything except the hwmon interfaces to THERM")
> Cc: stable@vger.kernel.org
> Signed-off-by: liupeng <liupeng01@kylinos.cn>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260922044044.21442-1-liupeng01@kylinos.cn?part=1


^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: [PATCH v2] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths
  2026-09-22  4:40   ` [PATCH v2] " liupeng
  2026-09-22  4:46     ` sashiko-bot
@ 2026-10-08 21:45     ` lyude
  2026-10-09 11:51       ` [PATCH v3] " liupeng
  1 sibling, 1 reply; 11+ messages in thread
From: lyude @ 2026-10-08 21:45 UTC (permalink / raw)
  To: liupeng, dakr
  Cc: maarten.lankhorst, mripard, tzimmermann, airlied, simona, linux,
	nouveau, bskeggs, dri-devel, nouveau, linux-kernel, linux-hwmon,
	stable

One nit-pick below:

On Tue, 2026-09-22 at 12:40 +0800, liupeng wrote:
> In nouveau_debugfs_init(), if nvif_object_ctor() fails, the
> previously
> allocated drm->debugfs is leaked because the function returns the
> error code directly.
> 
> In nouveau_hwmon_init(), if hwmon_device_register_with_info() fails,
> the allocated hwmon structure is leaked because the function returns
> the error code directly.
> 
> Fix both by freeing the allocated memory and clearing the pointer on
> the error paths.
> 
> Fixes: b126a200e9db ("drm/nouveau/debugfs: we need a ctrl object for
> debugfs")
> Fixes: b9ed919f1c8f ("drm/nouveau/drm/pm: remove everything except
> the hwmon interfaces to THERM")
> Cc: stable@vger.kernel.org
> Signed-off-by: liupeng <liupeng01@kylinos.cn>
> ---
> Changes in v2:
> - Add Fixes: tags for the commits that introduced the leaks
> - Add Cc: stable@vger.kernel.org for stable backporting
> 
>  drivers/gpu/drm/nouveau/nouveau_debugfs.c | 15 ++++++++++++---
>  drivers/gpu/drm/nouveau/nouveau_hwmon.c   |  2 ++
>  2 files changed, 14 insertions(+), 3 deletions(-)
> 
> diff --git a/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> index 47d5579c568d..88223931f382 100644
> --- a/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> +++ b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> @@ -295,13 +295,22 @@ nouveau_drm_debugfs_init(struct drm_minor
> *minor)
>  int
>  nouveau_debugfs_init(struct nouveau_drm *drm)
>  {
> +	int ret;
> +
>  	drm->debugfs = kzalloc_obj(*drm->debugfs);
>  	if (!drm->debugfs)
>  		return -ENOMEM;
>  
> -	return nvif_object_ctor(&drm->client.device.object,
> "debugfsCtrl", 0,
> -				NVIF_CLASS_CONTROL, NULL, 0,
> -				&drm->debugfs->ctrl);
> +	ret = nvif_object_ctor(&drm->client.device.object,
> "debugfsCtrl", 0,
> +			       NVIF_CLASS_CONTROL, NULL, 0,
> +			       &drm->debugfs->ctrl);
> +	if (ret) {
> +		kfree(drm->debugfs);
> +		drm->debugfs = NULL;
> +		return ret;

^ We could get rid of this extra return…

> +	}
> +
> +	return 0;

…and just return ret here

With that fixed:

Reviewed-by: Lyude Paul <lyude@redhat.com>
>  }
>  
>  void
> diff --git a/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> index 726397ab035d..ffbe7f542ab0 100644
> --- a/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> +++ b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> @@ -697,6 +697,8 @@ nouveau_hwmon_init(struct drm_device *dev)
>  	if (IS_ERR(hwmon_dev)) {
>  		ret = PTR_ERR(hwmon_dev);
>  		NV_ERROR(drm, "Unable to register hwmon device:
> %d\n", ret);
> +		drm->hwmon = NULL;
> +		kfree(hwmon);
>  		return ret;
>  	}
>  


^ permalink raw reply	[flat|nested] 11+ messages in thread

* [PATCH v3] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths
  2026-10-08 21:45     ` lyude
@ 2026-10-09 11:51       ` liupeng
  2026-10-09 12:00         ` sashiko-bot
  2026-10-09 21:35         ` lyude
  0 siblings, 2 replies; 11+ messages in thread
From: liupeng @ 2026-10-09 11:51 UTC (permalink / raw)
  To: lyude, dakr
  Cc: maarten.lankhorst, mripard, tzimmermann, airlied, simona, linux,
	nouveau, bskeggs, dri-devel, nouveau, linux-kernel, linux-hwmon,
	stable, liupeng

In nouveau_debugfs_init(), if nvif_object_ctor() fails, the previously
allocated drm->debugfs is leaked because the function returns the
error code directly.

In nouveau_hwmon_init(), if hwmon_device_register_with_info() fails,
the allocated hwmon structure is leaked because the function returns
the error code directly.

Fix both by freeing the allocated memory and clearing the pointer on
the error paths.

Fixes: b126a200e9db ("drm/nouveau/debugfs: we need a ctrl object for debugfs")
Fixes: b9ed919f1c8f ("drm/nouveau/drm/pm: remove everything except the hwmon interfaces to THERM")
Cc: stable@vger.kernel.org
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: liupeng <liupeng01@kylinos.cn>
---
Changes in v3:
- Drop the extra return in nouveau_debugfs_init() as suggested by Lyude.
- Add Reviewed-by tag.

 drivers/gpu/drm/nouveau/nouveau_debugfs.c | 14 +++++++++++---
 drivers/gpu/drm/nouveau/nouveau_hwmon.c   |  2 ++
 2 files changed, 13 insertions(+), 3 deletions(-)

diff --git a/drivers/gpu/drm/nouveau/nouveau_debugfs.c b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
index 47d5579c568d..338421e52f69 100644
--- a/drivers/gpu/drm/nouveau/nouveau_debugfs.c
+++ b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
@@ -295,13 +295,21 @@ nouveau_drm_debugfs_init(struct drm_minor *minor)
 int
 nouveau_debugfs_init(struct nouveau_drm *drm)
 {
+	int ret;
+
 	drm->debugfs = kzalloc_obj(*drm->debugfs);
 	if (!drm->debugfs)
 		return -ENOMEM;
 
-	return nvif_object_ctor(&drm->client.device.object, "debugfsCtrl", 0,
-				NVIF_CLASS_CONTROL, NULL, 0,
-				&drm->debugfs->ctrl);
+	ret = nvif_object_ctor(&drm->client.device.object, "debugfsCtrl", 0,
+			       NVIF_CLASS_CONTROL, NULL, 0,
+			       &drm->debugfs->ctrl);
+	if (ret) {
+		kfree(drm->debugfs);
+		drm->debugfs = NULL;
+	}
+
+	return ret;
 }
 
 void
diff --git a/drivers/gpu/drm/nouveau/nouveau_hwmon.c b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
index 726397ab035d..ffbe7f542ab0 100644
--- a/drivers/gpu/drm/nouveau/nouveau_hwmon.c
+++ b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
@@ -697,6 +697,8 @@ nouveau_hwmon_init(struct drm_device *dev)
 	if (IS_ERR(hwmon_dev)) {
 		ret = PTR_ERR(hwmon_dev);
 		NV_ERROR(drm, "Unable to register hwmon device: %d\n", ret);
+		drm->hwmon = NULL;
+		kfree(hwmon);
 		return ret;
 	}
 
-- 
2.53.0


^ permalink raw reply related	[flat|nested] 11+ messages in thread

* Re: [PATCH v3] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths
  2026-10-09 11:51       ` [PATCH v3] " liupeng
@ 2026-10-09 12:00         ` sashiko-bot
  2026-10-09 21:35         ` lyude
  1 sibling, 0 replies; 11+ messages in thread
From: sashiko-bot @ 2026-10-09 12:00 UTC (permalink / raw)
  To: liupeng; +Cc: dri-devel, linux-hwmon

> In nouveau_debugfs_init(), if nvif_object_ctor() fails, the previously
> allocated drm->debugfs is leaked because the function returns the
> error code directly.
> 
> In nouveau_hwmon_init(), if hwmon_device_register_with_info() fails,
> the allocated hwmon structure is leaked because the function returns
> the error code directly.
> 
> Fix both by freeing the allocated memory and clearing the pointer on
> the error paths.
> 
> Fixes: b126a200e9db ("drm/nouveau/debugfs: we need a ctrl object for debugfs")
> Fixes: b9ed919f1c8f ("drm/nouveau/drm/pm: remove everything except the hwmon interfaces to THERM")
> Cc: stable@vger.kernel.org
> Reviewed-by: Lyude Paul <lyude@redhat.com>
> Signed-off-by: liupeng <liupeng01@kylinos.cn>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261009115151.13877-1-liupeng01@kylinos.cn?part=1


^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: [PATCH v3] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths
  2026-10-09 11:51       ` [PATCH v3] " liupeng
  2026-10-09 12:00         ` sashiko-bot
@ 2026-10-09 21:35         ` lyude
  2026-10-09 21:40           ` Danilo Krummrich
  1 sibling, 1 reply; 11+ messages in thread
From: lyude @ 2026-10-09 21:35 UTC (permalink / raw)
  To: liupeng, dakr
  Cc: maarten.lankhorst, mripard, tzimmermann, airlied, simona, linux,
	nouveau, bskeggs, dri-devel, nouveau, linux-kernel, linux-hwmon,
	stable

Reviewed-by: Lyude Paul <lyude@redhat.com>

Will push to drm-misc-fixes in a moment

On Fri, 2026-10-09 at 19:51 +0800, liupeng wrote:
> In nouveau_debugfs_init(), if nvif_object_ctor() fails, the
> previously
> allocated drm->debugfs is leaked because the function returns the
> error code directly.
> 
> In nouveau_hwmon_init(), if hwmon_device_register_with_info() fails,
> the allocated hwmon structure is leaked because the function returns
> the error code directly.
> 
> Fix both by freeing the allocated memory and clearing the pointer on
> the error paths.
> 
> Fixes: b126a200e9db ("drm/nouveau/debugfs: we need a ctrl object for
> debugfs")
> Fixes: b9ed919f1c8f ("drm/nouveau/drm/pm: remove everything except
> the hwmon interfaces to THERM")
> Cc: stable@vger.kernel.org
> Reviewed-by: Lyude Paul <lyude@redhat.com>
> Signed-off-by: liupeng <liupeng01@kylinos.cn>
> ---
> Changes in v3:
> - Drop the extra return in nouveau_debugfs_init() as suggested by
> Lyude.
> - Add Reviewed-by tag.
> 
>  drivers/gpu/drm/nouveau/nouveau_debugfs.c | 14 +++++++++++---
>  drivers/gpu/drm/nouveau/nouveau_hwmon.c   |  2 ++
>  2 files changed, 13 insertions(+), 3 deletions(-)
> 
> diff --git a/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> index 47d5579c568d..338421e52f69 100644
> --- a/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> +++ b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> @@ -295,13 +295,21 @@ nouveau_drm_debugfs_init(struct drm_minor
> *minor)
>  int
>  nouveau_debugfs_init(struct nouveau_drm *drm)
>  {
> +	int ret;
> +
>  	drm->debugfs = kzalloc_obj(*drm->debugfs);
>  	if (!drm->debugfs)
>  		return -ENOMEM;
>  
> -	return nvif_object_ctor(&drm->client.device.object,
> "debugfsCtrl", 0,
> -				NVIF_CLASS_CONTROL, NULL, 0,
> -				&drm->debugfs->ctrl);
> +	ret = nvif_object_ctor(&drm->client.device.object,
> "debugfsCtrl", 0,
> +			       NVIF_CLASS_CONTROL, NULL, 0,
> +			       &drm->debugfs->ctrl);
> +	if (ret) {
> +		kfree(drm->debugfs);
> +		drm->debugfs = NULL;
> +	}
> +
> +	return ret;
>  }
>  
>  void
> diff --git a/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> index 726397ab035d..ffbe7f542ab0 100644
> --- a/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> +++ b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> @@ -697,6 +697,8 @@ nouveau_hwmon_init(struct drm_device *dev)
>  	if (IS_ERR(hwmon_dev)) {
>  		ret = PTR_ERR(hwmon_dev);
>  		NV_ERROR(drm, "Unable to register hwmon device:
> %d\n", ret);
> +		drm->hwmon = NULL;
> +		kfree(hwmon);
>  		return ret;
>  	}
>  


^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: [PATCH v3] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths
  2026-10-09 21:35         ` lyude
@ 2026-10-09 21:40           ` Danilo Krummrich
  2026-10-09 21:43             ` lyude
  0 siblings, 1 reply; 11+ messages in thread
From: Danilo Krummrich @ 2026-10-09 21:40 UTC (permalink / raw)
  To: lyude
  Cc: liupeng, maarten.lankhorst, mripard, tzimmermann, airlied, simona,
	linux, nouveau, bskeggs, dri-devel, nouveau, linux-kernel,
	linux-hwmon, stable

On Fri Oct 9, 2026 at 11:35 PM CEST, lyude wrote:
> Reviewed-by: Lyude Paul <lyude@redhat.com>
>
> Will push to drm-misc-fixes in a moment

Please wait, those are two unrelated fixes with two different Fixes: tags, so
those should be two separate patches.

I'm also not sure this is -fixes material. A memory leak in an unwind path for
-rc7 feels wrong.

Thanks,
Danilo

> On Fri, 2026-10-09 at 19:51 +0800, liupeng wrote:
>> In nouveau_debugfs_init(), if nvif_object_ctor() fails, the
>> previously
>> allocated drm->debugfs is leaked because the function returns the
>> error code directly.
>> 
>> In nouveau_hwmon_init(), if hwmon_device_register_with_info() fails,
>> the allocated hwmon structure is leaked because the function returns
>> the error code directly.
>> 
>> Fix both by freeing the allocated memory and clearing the pointer on
>> the error paths.
>> 
>> Fixes: b126a200e9db ("drm/nouveau/debugfs: we need a ctrl object for
>> debugfs")
>> Fixes: b9ed919f1c8f ("drm/nouveau/drm/pm: remove everything except
>> the hwmon interfaces to THERM")
>> Cc: stable@vger.kernel.org
>> Reviewed-by: Lyude Paul <lyude@redhat.com>
>> Signed-off-by: liupeng <liupeng01@kylinos.cn>
>> ---
>> Changes in v3:
>> - Drop the extra return in nouveau_debugfs_init() as suggested by
>> Lyude.
>> - Add Reviewed-by tag.
>> 
>>  drivers/gpu/drm/nouveau/nouveau_debugfs.c | 14 +++++++++++---
>>  drivers/gpu/drm/nouveau/nouveau_hwmon.c   |  2 ++
>>  2 files changed, 13 insertions(+), 3 deletions(-)
>> 
>> diff --git a/drivers/gpu/drm/nouveau/nouveau_debugfs.c
>> b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
>> index 47d5579c568d..338421e52f69 100644
>> --- a/drivers/gpu/drm/nouveau/nouveau_debugfs.c
>> +++ b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
>> @@ -295,13 +295,21 @@ nouveau_drm_debugfs_init(struct drm_minor
>> *minor)
>>  int
>>  nouveau_debugfs_init(struct nouveau_drm *drm)
>>  {
>> +	int ret;
>> +
>>  	drm->debugfs = kzalloc_obj(*drm->debugfs);
>>  	if (!drm->debugfs)
>>  		return -ENOMEM;
>>  
>> -	return nvif_object_ctor(&drm->client.device.object,
>> "debugfsCtrl", 0,
>> -				NVIF_CLASS_CONTROL, NULL, 0,
>> -				&drm->debugfs->ctrl);
>> +	ret = nvif_object_ctor(&drm->client.device.object,
>> "debugfsCtrl", 0,
>> +			       NVIF_CLASS_CONTROL, NULL, 0,
>> +			       &drm->debugfs->ctrl);
>> +	if (ret) {
>> +		kfree(drm->debugfs);
>> +		drm->debugfs = NULL;
>> +	}
>> +
>> +	return ret;
>>  }
>>  
>>  void
>> diff --git a/drivers/gpu/drm/nouveau/nouveau_hwmon.c
>> b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
>> index 726397ab035d..ffbe7f542ab0 100644
>> --- a/drivers/gpu/drm/nouveau/nouveau_hwmon.c
>> +++ b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
>> @@ -697,6 +697,8 @@ nouveau_hwmon_init(struct drm_device *dev)
>>  	if (IS_ERR(hwmon_dev)) {
>>  		ret = PTR_ERR(hwmon_dev);
>>  		NV_ERROR(drm, "Unable to register hwmon device:
>> %d\n", ret);
>> +		drm->hwmon = NULL;
>> +		kfree(hwmon);
>>  		return ret;
>>  	}
>>  


^ permalink raw reply	[flat|nested] 11+ messages in thread

* Re: [PATCH v3] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths
  2026-10-09 21:40           ` Danilo Krummrich
@ 2026-10-09 21:43             ` lyude
  0 siblings, 0 replies; 11+ messages in thread
From: lyude @ 2026-10-09 21:43 UTC (permalink / raw)
  To: Danilo Krummrich
  Cc: liupeng, maarten.lankhorst, mripard, tzimmermann, airlied, simona,
	linux, nouveau, bskeggs, dri-devel, nouveau, linux-kernel,
	linux-hwmon, stable

On Fri, 2026-10-09 at 23:40 +0200, Danilo Krummrich wrote:
> On Fri Oct 9, 2026 at 11:35 PM CEST, lyude wrote:
> > Reviewed-by: Lyude Paul <lyude@redhat.com>
> > 
> > Will push to drm-misc-fixes in a moment
> 
> Please wait, those are two unrelated fixes with two different Fixes:
> tags, so
> those should be two separate patches.

Thanks, I think my brain just glossed over the tags while looking at
this.

liupeng, could you split these patches up?

> 
> I'm also not sure this is -fixes material. A memory leak in an unwind
> path for
> -rc7 feels wrong.
> 
> Thanks,
> Danilo
> 
> > On Fri, 2026-10-09 at 19:51 +0800, liupeng wrote:
> > > In nouveau_debugfs_init(), if nvif_object_ctor() fails, the
> > > previously
> > > allocated drm->debugfs is leaked because the function returns the
> > > error code directly.
> > > 
> > > In nouveau_hwmon_init(), if hwmon_device_register_with_info()
> > > fails,
> > > the allocated hwmon structure is leaked because the function
> > > returns
> > > the error code directly.
> > > 
> > > Fix both by freeing the allocated memory and clearing the pointer
> > > on
> > > the error paths.
> > > 
> > > Fixes: b126a200e9db ("drm/nouveau/debugfs: we need a ctrl object
> > > for
> > > debugfs")
> > > Fixes: b9ed919f1c8f ("drm/nouveau/drm/pm: remove everything
> > > except
> > > the hwmon interfaces to THERM")
> > > Cc: stable@vger.kernel.org
> > > Reviewed-by: Lyude Paul <lyude@redhat.com>
> > > Signed-off-by: liupeng <liupeng01@kylinos.cn>
> > > ---
> > > Changes in v3:
> > > - Drop the extra return in nouveau_debugfs_init() as suggested by
> > > Lyude.
> > > - Add Reviewed-by tag.
> > > 
> > >  drivers/gpu/drm/nouveau/nouveau_debugfs.c | 14 +++++++++++---
> > >  drivers/gpu/drm/nouveau/nouveau_hwmon.c   |  2 ++
> > >  2 files changed, 13 insertions(+), 3 deletions(-)
> > > 
> > > diff --git a/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> > > b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> > > index 47d5579c568d..338421e52f69 100644
> > > --- a/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> > > +++ b/drivers/gpu/drm/nouveau/nouveau_debugfs.c
> > > @@ -295,13 +295,21 @@ nouveau_drm_debugfs_init(struct drm_minor
> > > *minor)
> > >  int
> > >  nouveau_debugfs_init(struct nouveau_drm *drm)
> > >  {
> > > +	int ret;
> > > +
> > >  	drm->debugfs = kzalloc_obj(*drm->debugfs);
> > >  	if (!drm->debugfs)
> > >  		return -ENOMEM;
> > >  
> > > -	return nvif_object_ctor(&drm->client.device.object,
> > > "debugfsCtrl", 0,
> > > -				NVIF_CLASS_CONTROL, NULL, 0,
> > > -				&drm->debugfs->ctrl);
> > > +	ret = nvif_object_ctor(&drm->client.device.object,
> > > "debugfsCtrl", 0,
> > > +			       NVIF_CLASS_CONTROL, NULL, 0,
> > > +			       &drm->debugfs->ctrl);
> > > +	if (ret) {
> > > +		kfree(drm->debugfs);
> > > +		drm->debugfs = NULL;
> > > +	}
> > > +
> > > +	return ret;
> > >  }
> > >  
> > >  void
> > > diff --git a/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> > > b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> > > index 726397ab035d..ffbe7f542ab0 100644
> > > --- a/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> > > +++ b/drivers/gpu/drm/nouveau/nouveau_hwmon.c
> > > @@ -697,6 +697,8 @@ nouveau_hwmon_init(struct drm_device *dev)
> > >  	if (IS_ERR(hwmon_dev)) {
> > >  		ret = PTR_ERR(hwmon_dev);
> > >  		NV_ERROR(drm, "Unable to register hwmon device:
> > > %d\n", ret);
> > > +		drm->hwmon = NULL;
> > > +		kfree(hwmon);
> > >  		return ret;
> > >  	}
> > >  


^ permalink raw reply	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2026-10-09 21:44 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-24  9:05 [PATCH] drm/nouveau: Fix memory leaks in debugfs and hwmon init error paths liupeng
2026-08-24  9:12 ` sashiko-bot
2026-09-17 22:10 ` lyude
2026-09-22  4:40   ` [PATCH v2] " liupeng
2026-09-22  4:46     ` sashiko-bot
2026-10-08 21:45     ` lyude
2026-10-09 11:51       ` [PATCH v3] " liupeng
2026-10-09 12:00         ` sashiko-bot
2026-10-09 21:35         ` lyude
2026-10-09 21:40           ` Danilo Krummrich
2026-10-09 21:43             ` lyude

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox